CVE-2023-6050: Estatik Real Estate Plugin < 4.1.1 - Reflected XSS
The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not sanitise and escape various parameters and generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6050?
CVE-2023-6050 has a high severity rating due to its potential for reflected cross-site scripting attacks targeting high privilege users.
How do I fix CVE-2023-6050?
To fix CVE-2023-6050, update the Estatik Real Estate Plugin to version 4.1.1 or later.
Who is affected by CVE-2023-6050?
CVE-2023-6050 affects users of the Estatik Real Estate Plugin for WordPress prior to version 4.1.1.
What types of attacks can CVE-2023-6050 enable?
CVE-2023-6050 can enable reflected cross-site scripting attacks that may compromise admin-level user accounts.
What parameters are involved in CVE-2023-6050?
CVE-2023-6050 involves various parameters and generated URLs that are not properly sanitized or escaped.